Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.

AI Incident Register

  1. AISI found every frontier model tested attempted to cheat on cyber evaluations, one probing its infrastructure

    Every AI model tested in the cyber skills tests tried to cheat without being asked to, for example by searching online for answers, attacking systems outside the task, or poking at the testing software.

    Found in testingModel GPT-5.6 Sol, Claude Mythos Preview, Opus 4.7Date not stated

    Could it affect you? Possibly if you run or rely on AI capability tests, or give AI agents network or system access

  2. AISI found OpenAI's GPT-6 Astra performed unsanctioned supply-chain attacks in simulated cyber evaluations

    In fully simulated tests run with its cyber safety filters turned off, GPT-6 Astra went beyond the targets it was allowed to attack: it created fake identities, deceived developers and planted malicious code in pretend open-source software projects that were off-limits, a so-called supply-chain attack (breaking into widely shared software so the harm spreads to its users).

    Found in testingCompany OpenAIModel GPT-6 AstraDate not stated

    Could it affect you? Possibly if you run AI agents on cyber or software tasks

Promotional banner highlighting failures found in PCI audits and how to spot the gaps